Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 51 of 152
CVE-2018-0974P4MEDIUMCVSS 5.5PoCvr22018-04-12
CVE-2018-0974 [MEDIUM] CVE-2018-0974: An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 20
nvd
CVE-2017-0299P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-0299 [MEDIUM] CVE-2017-0299: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2023-21543P3HIGHCVSS 8.1vr22023-01-10
CVE-2023-21543 [HIGH] CWE-400 CVE-2023-21543: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2017-8685P4MEDIUMCVSS 5.5PoCvr22017-09-13
CVE-2017-8685 [MEDIUM] CVE-2017-8685: Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information d
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and CVE-2017-8688.
nvd
CVE-2018-0975P4MEDIUMCVSS 5.5PoCvr22018-04-12
CVE-2018-0975 [MEDIUM] CVE-2018-0975: An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 20
nvd
CVE-2017-11785P4MEDIUMCVSS 5.5PoCvr22017-10-13
CVE-2017-11785 [MEDIUM] CVE-2017-11785: The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Discl
nvd
CVE-2017-8564P4MEDIUMCVSS 5.5PoCvr22017-07-11
CVE-2017-8564 [MEDIUM] CWE-200 CVE-2017-8564: Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulne
nvd
CVE-2019-0598P3HIGHCVSS 7.8vr22019-03-05
CVE-2019-0598 [HIGH] CVE-2019-0598: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0597, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2019-0599P3HIGHCVSS 7.8vr22019-03-05
CVE-2019-0599 [HIGH] CVE-2019-0599: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2019-0625.
nvd
CVE-2019-1344P4MEDIUMCVSS 5.5PoCvr22019-10-10
CVE-2019-1344 [MEDIUM] CWE-125 CVE-2019-1344: An information disclosure vulnerability exists in the way that the Windows Code Integrity Module han
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'.
nvd
CVE-2019-1153P4MEDIUMCVSS 5.5PoCvr22019-08-14
CVE-2019-1153 [MEDIUM] CWE-125 CVE-2019-1153: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1148P4MEDIUMCVSS 5.5PoCvr22019-08-14
CVE-2019-1148 [MEDIUM] CWE-125 CVE-2019-1148: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2024-30020P3HIGHCVSS 8.1vr22024-05-14
CVE-2024-30020 [HIGH] CWE-122 CVE-2024-30020: Windows Cryptographic Services Remote Code Execution Vulnerability
Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-49126P3HIGHCVSS 8.1vr22024-12-12
CVE-2024-49126 [HIGH] CWE-416 CVE-2024-49126: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2025-26671P3HIGHCVSS 8.1vr22025-04-08
CVE-2025-26671 [HIGH] CWE-416 CVE-2025-26671: Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code ov
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2017-8563P3HIGHCVSS 8.1vr22017-07-11
CVE-2017-8563 [HIGH] CWE-281 CVE-2017-8563: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to NT LAN Manager (NTLM) Authentication Protocol as the default authentication protocol, aka "Windo
nvd
CVE-2025-27487P3HIGHCVSS 8.0vr22025-04-08
CVE-2025-27487 [HIGH] CWE-122 CVE-2025-27487: Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code ov
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
nvd
CVE-2025-32710P3HIGHCVSS 8.1vr22025-06-10
CVE-2025-32710 [HIGH] CWE-362 CVE-2025-32710: Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code ov
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-8432P3HIGHCVSS 7.8vr2-sp1v32-bit Systems Service Pack 2+4 more2018-10-10
CVE-2018-8432 [HIGH] CVE-2018-8432: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Windows Server 2019, Windows
nvd
CVE-2019-0617P3HIGHCVSS 7.8vr22019-04-08
CVE-2019-0617 [HIGH] CVE-2019-0617: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd